Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    New Windows Defender zero-day blocks Microsoft antivirus updates

    September 22, 2026

    CISA orders feds to patch Zyxel flaw exploited for data theft

    September 22, 2026

    OpenAI Turned Off the Guardrails | Threat Wire

    September 22, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»New Windows Defender zero-day blocks Microsoft antivirus updates
    News

    New Windows Defender zero-day blocks Microsoft antivirus updates

    adminBy adminSeptember 22, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Microsoft Defender

    Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates.

    Naceri named it BigDiskBuster and said it is similar to another Defender zero-day known as UnDefend, which he released in April and that allowed standard users to block definition updates.

    The security researcher added that BigDiskBuster works on all supported Windows versions and that it needs to run in the background to block Defender updates.

    “Made a funny tool, completely denies defender from updating so you’re stuck with your current version if the tool is running in the background,” he said.

    “This proof of concept is similar to UnDefend, it prevents windows defender from performing platform/signature updates. Seems to work on all supported windows versions but PoC is a bit buggy and needs some rewritting but you get the idea.”

    BigDiskBuster tweet

    Since April 2026, Naceri has released almost a dozen zero-day exploits as part of an ongoing dispute with Microsoft over their alleged unfair termination in March 2025.

    Two weeks ago, they released another Defender zero-day exploit that grants SYSTEM access (known as ‘ShieldCrash‘) right after Microsoft rolled out this month’s Patch Tuesday security updates.

    According to Naceri, ShieldCrash bypasses another ShieldBreak Defender privilege escalation flaw patched a week earlier, which itself bypassed RoguePlanet, another Defender flaw the security researcher disclosed in June and Microsoft patched in July.

    Naceri’s zero-day exploits released this year also include LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend, which target Microsoft Defender, BitLocker, and other Windows components.

    Microsoft initially responded with warnings of legal action against anyone engaging in “malicious activity causing real harm” to the company’s customers, leading many in the infosec community to believe that Microsoft was directly threatening the security researcher.

    While Microsoft has fixed some of the security flaws Naceri disclosed (such as ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma flaws), the other security issues still lack an official patch.

    A Microsoft spokesperson was not immediately available to comment when BleepingComputer reached out about the BigDiskBuster denial-of-service zero-day.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCISA orders feds to patch Zyxel flaw exploited for data theft
    admin
    • Website

    Related Posts

    News

    CISA orders feds to patch Zyxel flaw exploited for data theft

    September 22, 2026
    News

    Microsoft to retire Microsoft 365 Companion apps in December

    September 22, 2026
    News

    WordPress Click2Shell flaw lets hackers execute PHP on the server

    September 21, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Our Picks

    New Windows Defender zero-day blocks Microsoft antivirus updates

    September 22, 2026

    CISA orders feds to patch Zyxel flaw exploited for data theft

    September 22, 2026

    OpenAI Turned Off the Guardrails | Threat Wire

    September 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.